<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Restrict Apps a User can View when Configuring Okta AWS CLI for Multiple AWS Environments

Okta Identity Engine
SDKs & Libraries

Overview

The okta-aws-cli utility can be configured so a single OIDC Application can work with multiple AWS Federation Applications. When configuring the CLI for multiple AWS Applications users assigned to the application require Admin Read Rights for Applications in Okta.
This can provide unwanted read access to apps for these users.

Applies To

  • Okta Identity Engine 
  • okta-aws-cli
  • Okta AWS Federation Application (SAML)

Cause

In order for the CLI to retrieve the AWS Federation application instances in an Okta Org, users need to be part of an Admin group with enough permissions to satisfy the Okta scope 'okta.apps.read'. Builtin Okta Admin groups will give users access to all applications, not just the AWS Federation Applications.

Solution

Navigate to Security > Administrators

Create a Role:
  • Select the 'roles' tab and click 'create new role'
  • Provide a name and description
  • For 'View by type' select 'Application' only
  • Under 'Application permissions' select 'View application and their details', then save
Create a Resource Set:
  • Select the 'Resources' tab and click 'Create new resource set'
  • Provide a name and description
  • Click 'Add Resource'
  • Type 'Applications' and select it
  • Click 'Select Applications'
  • Type 'AWS', then select 'All AWS Account Federation Apps'
  • Click Create
Add Admin with new Role / Resource Set:
  • Select the 'Admins' tab and click 'Add Administrator'
  • Under 'Select Admin' type a username or group to add
  • Under 'role' select the role created
  • Under 'Resource Set' select the resource set created
  • Save
     
Loading
Restrict Apps a User can View when Configuring Okta AWS CLI for Multiple AWS Environments | Okta Support